Security Advisory

CVE-2025-4086

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-04-29 13:13:40
Last updated 2026-04-13 14:28:45
Assigner mozilla
State PUBLISHED

Description

A specially crafted filename containing a large number of encoded newline characters could obscure the files extension when displayed in the download dialog. *This bug only affects Thunderbird for Android. Other versions of Thunderbird are unaffected.*. This vulnerability was fixed in Firefox 138 and Thunderbird 138.